Skip to content

Scoring

Five outside services rate this repository, and each one measures something different. This page lists every item each rater scores, what it saw, and where the gaps are, so a badge at the top of the README reads down to the line that earned it.

The page is generated by scripts/render_scoring.py from a snapshot of the raters' own data, scoring/snapshot.json; a gate fails the build when the page and the snapshot disagree, and only a deliberate refresh reads the raters again, so every date here is a date something was actually read. Snapshot taken 2026-09-30, UTC.

Rater Result What it measures
OpenSSF Scorecard 8.2 / 10 supply-chain and project security practices, read from the repository by a scanner
OpenSSF Best Practices passing criteria for open source projects, each answered with a justification the site publishes
build-doctrine score 3.5 / 5 how far each rule of the program's own doctrine is enforced here, from stated to gated and proven
Codecov 95.02 percent line coverage of the application by its test suite
SonarCloud quality gate ok static analysis of new code: reliability, security, maintainability, duplication, coverage

OpenSSF Scorecard

Scorecard v5.5.0 read commit d4e4220ddf54 on 2026-09-30. Each check scores 0 to 10 and the overall score is a risk-weighted average; a check that returns -1 is inconclusive and is left out of the average. The scanner documents every check, with its risk and its scoring, in checks.md.

Check Risk Score What the scanner saw
Binary-Artifacts High 10 no binaries found in the repo
Branch-Protection High 4 branch protection is not maximal on development and all release branches
CI-Tests Low 10 12 out of 12 merged PRs checked by a CI test -- score normalized to 10
CII-Best-Practices Low 5 badge detected: Passing
Code-Review High -1 Found no human activity in the last 12 changesets
Contributors Low 3 project has 1 contributing companies or organizations -- score normalized to 3
Dangerous-Workflow Critical 10 no dangerous workflow patterns detected
Dependency-Update-Tool High 10 update tool detected
Fuzzing Medium 10 project is fuzzed
License Low 10 license file detected
Maintained High 0 project was created within the last 90 days. Please review its contents carefully
Packaging Medium 10 packaging workflow detected
Pinned-Dependencies Medium 10 all dependencies are pinned
SAST Medium 10 SAST tool is run on all commits
Security-Policy Medium 10 security policy file detected
Signed-Releases High 10 1 out of the last 1 releases have a total of 1 signed artifacts.
Token-Permissions High 10 GitHub workflow tokens follow principle of least privilege
Vulnerabilities High 7 3 existing vulnerabilities detected

The checks below ten

What each check reads, and the scanner's own detail lines for the ones that did not reach ten.

  • Branch-Protection, 4: reads the default and release branches refuse unreviewed merges.
    • Info: 'allow deletion' disabled on branch 'main'
    • Info: 'force pushes' disabled on branch 'main'
    • Info: 'branch protection settings apply to administrators' is required to merge on branch 'main'
    • Info: 'stale review dismissal' is required to merge on branch 'main'
    • Warn: required approving review count is 1 on branch 'main'
    • Info: codeowner review is required on branch 'main'
    • Warn: 'last push approval' is disabled on branch 'main'
    • Warn: 'up-to-date branches' is disabled on branch 'main'
    • Info: status check found to merge onto on branch 'main'
    • Info: PRs are required in order to make changes on branch 'main'
  • CII-Best-Practices, 5: reads an OpenSSF Best Practices badge, scored by its level.
  • Code-Review, -1: reads recent changes were reviewed by a person other than their author.
  • Contributors, 3: reads recent contributors from more than one company or organization.
    • Info: found contributions from: manifest-identity
  • Maintained, 0: reads recent commits and issue activity over the last ninety days.
    • Warn: Repository was created within the last 90 days.
  • Vulnerabilities, 7: reads no open, unfixed vulnerabilities in the project or its packages.
    • Warn: Project is vulnerable to: https://osv.dev/GHSA-8988-9cw3-xx77
    • Warn: Project is vulnerable to: https://osv.dev/GHSA-gh4c-6fx4-qh6g
    • Warn: Project is vulnerable to: https://osv.dev/GHSA-vxq7-64xx-v4gw

OpenSSF Best Practices

The entry is project 14563, at the passing level with 100 percent of that level's criteria met, achieved 2026-09-10 and last edited 2026-09-30. Every answer is a claim the badge holder makes, so each row below carries the justification exactly as the entry states it; the gates and tests named in them are the ones this repository runs.

Basics

Criterion Status Justification
description_good Met The README at https://github.com/manifest-identity/manifest-identity#readme opens by stating what the software does, two records about every identity and the difference between them, and the problem it addresses.
interact Met Issues and pull requests are open on GitHub; https://github.com/manifest-identity/manifest-identity/blob/main/CONTRIBUTING.md states how to propose changes and report problems.
contribution Met https://github.com/manifest-identity/manifest-identity/blob/main/CONTRIBUTING.md: every change travels a branch and a pull request through the documented gates.
contribution_requirements Met https://github.com/manifest-identity/manifest-identity/blob/main/CONTRIBUTING.md names the gates, the writing rules, and the requirement that counted figures move with the change.
floss_license Met AGPL-3.0.
floss_license_osi Met AGPL-3.0 is OSI approved.
license_location Met https://github.com/manifest-identity/manifest-identity/blob/main/LICENSE
documentation_basics Met The README (https://github.com/manifest-identity/manifest-identity#readme) documents installation by compose, SQLite, and Kubernetes, use under "Using it", and the full API surface under "How it is put together"; the same documents render as a site at https://manifest-identity.github.io/manifest-identity/.
documentation_interface Met The routes block in the README is gated by a test against the application's actual route table, and the application serves interactive API documentation from FastAPI at /docs.
sites_https Met GitHub, HTTPS only.
discussion Met GitHub issues and pull requests.
english Met All documentation and discussion are in English.
maintained Met Actively developed: release v0.2.0 in August 2026 with changes merged weekly since, and a stated roadmap in the README.

Change control

Criterion Status Justification
repo_public Met https://github.com/manifest-identity/manifest-identity is public.
repo_track Met Git tracks every change; the mainline ruleset requires pull requests.
repo_interim Met Every interim change lands as a pull request on the public repository; nothing is batched into releases.
repo_distributed Met Git.
version_unique Met Tags of the form v0.x.y, one per release, see the release process recorded in DECISIONS.md (D-050).
version_semver Met Semantic versioning, v0.2.0 the current release.
version_tags Met Signed tags start the release workflow; https://github.com/manifest-identity/manifest-identity/tags
release_notes Met Each release at https://github.com/manifest-identity/manifest-identity/releases carries notes generated from the annotated tag message, and the README's "What comes next" section states the roadmap.
release_notes_vulns Met No vulnerabilities have needed fixing to date; SECURITY.md commits to naming any fixed vulnerability in the release notes.

Reporting

Criterion Status Justification
report_process Met GitHub issues, described in https://github.com/manifest-identity/manifest-identity/blob/main/CONTRIBUTING.md
report_tracker Met https://github.com/manifest-identity/manifest-identity/issues
report_responses Met https://github.com/manifest-identity/manifest-identity/blob/main/SECURITY.md commits to acknowledgment within seven days and a triage answer within fourteen.
enhancement_responses Met Enhancement requests are answered in the issue tracker on the same commitments.
report_archive Met https://github.com/manifest-identity/manifest-identity/issues?q=is%3Aissue
vulnerability_report_process Met https://github.com/manifest-identity/manifest-identity/blob/main/SECURITY.md: private reporting through GitHub security advisories.
vulnerability_report_private Met https://github.com/manifest-identity/manifest-identity/security/advisories/new
vulnerability_report_response Met Within fourteen days per SECURITY.md.

Quality

Criterion Status Justification
build Met Dockerfile and docker compose; pip installs with hash-verified requirements.
build_common_tools Met Docker, pip, Python.
build_floss_tools Met All build tooling is FLOSS.
test Met The pytest suite holds 422 tests in 45 files, run in continuous integration on every change and on the oldest supported interpreter.
test_invocation Met pytest -q, documented in AGENTS.md and in the README under "How it was built and gated".
test_most Met Coverage is 95 percent over a 90 percent floor enforced in CI, and a mutation check removes thirty-four controls one at a time and requires the suite to notice each.
test_continuous_integration Met GitHub Actions on every push and pull request; ten required checks gate the mainline.
test_policy Met AGENTS.md and CONTRIBUTING.md require tests for new functionality; counted README figures are recounted by a test so a new test must move the figure.
tests_are_added Met Every functional change in the history lands with its tests; the counted figures make an untested addition visible.
tests_documented_added Met https://github.com/manifest-identity/manifest-identity/blob/main/CONTRIBUTING.md
warnings Met ruff and mypy strict run in continuous integration.
warnings_fixed Met The pipeline is clean of warnings; a new warning fails the build.
warnings_strict Met mypy strict mode and the full ruff rule set.

Security

Criterion Status Justification
know_secure_design Met The README sections "How a request is protected" and "What it defends against", and the threat model in THREAT-MODEL.md.
know_common_errors Met Input handling is documented and tested: escaping at every exit, formula-safe CSV, text-only rendering, parameterized queries.
crypto_published Met Argon2id via passlib for passwords; TLS from the platform. No home-grown cryptography.
crypto_call Met Only library calls: passlib and the standard library secrets module.
crypto_floss Met passlib and CPython are FLOSS.
crypto_keylength Met Argon2id parameters at library defaults; tokens from secrets.token_urlsafe(32).
crypto_working Met No broken algorithms in use; MD5 and SHA-1 appear nowhere.
crypto_weaknesses Met No weak algorithms in use.
crypto_pfs N/A The application terminates no TLS itself; transport security is the deployment platform's.
crypto_password_storage Met Argon2id hashing with per-password salts via passlib.
crypto_random Met The secrets module for every token.
delivery_mitm Met HTTPS delivery, signed tags, and provenance attestations on release assets and the container image.
delivery_unsigned Met Build provenance attestations on every release asset, verifiable with gh attestation verify; https://github.com/manifest-identity/manifest-identity/releases
vulnerabilities_fixed_60_days Met No outstanding vulnerabilities; Dependabot alerts and security updates are enabled and reviewed.
vulnerabilities_critical_fixed Met None outstanding.
no_leaked_credentials Met TruffleHog scans the full history at every commit and in continuous integration, with verification against providers.

Analysis

Criterion Status Justification
static_analysis Met CodeQL on every commit and weekly, SonarCloud on every pull request and on main, and ruff and mypy strict.
static_analysis_common_vulnerabilities Met CodeQL security queries for Python and for workflow files.
static_analysis_fixed Met No open findings.
static_analysis_often Met Every commit.
dynamic_analysis Met ClusterFuzzLite fuzzes the two import parsers under AddressSanitizer on every pull request touching them and weekly, alongside property-based tests in the suite.
dynamic_analysis_unsafe N/A Memory-safe language (Python).
dynamic_analysis_enable_assertions Met pytest assertions are active in every run.
dynamic_analysis_fixed Met No open findings.

The silver and gold levels are not attempted. Both require more than one maintainer, and silver requires a code of conduct, which D-026 in the doctrine declines for a one-person program; a criterion marked met without its evidence would score zero on the doctrine's own scale, so the entry stops where the evidence stops.

build-doctrine score

The program's own doctrine, build-doctrine, scores each of its rules by how far the repository enforces it, and the badge is the mean over the rules that apply to an application repository. The scorer ran at doctrine commit a47b0cb94ca5.

Level Name Meaning
0 absent or false the rule is not met, or a claim about it is untrue
1 stated a document says it
2 attested a document says it and names where the evidence is
3 checked on demand a command anyone can run verifies it
4 gated the pipeline refuses a merge that breaks it
5 gated and proven gated, and the repository records a run where the gate fired
Rule Level What the scorer saw
readme 4 README.md present; this scorer runs in CI
license 4 LICENSE present; this scorer runs in CI
security-policy 4 SECURITY.md present; this scorer runs in CI
contributing 4 CONTRIBUTING.md present; this scorer runs in CI
decisions-record 4 84 numbered entries; a test recounts them
commit-subjects 4 all 14 recent subjects lead with an identifier; CI walks the messages
pinned-actions 5 all 29 uses are pinned by commit; a workflow audit gates it; proven: https://github.com/manifest-identity/manifest-identity/actions/runs/33565119678
ci-gate 4 10 required checks on the mainline: analyze (actions), analyze (python), application, container, doctrine, floor, links, secrets, workflows, writing
dependency-updates 3 update automation configured
run-instructions 1 README has a run section with a command block
troubleshooting 1 README names the likely failures
counted-figures 4 4 bold figures; a test recounts them from the source
generated-artifact-parity not applicable not applicable to an application repository

Mean over the applicable rules: 3.5. A rule at level one is one the repository states and nothing checks; a rule moves up only when a command, then a gate, then a recorded firing stands behind it, and the scorer never infers the fifth level.

Codecov

The pipeline's test run uploads its coverage report, and Codecov read 95.02 percent on 2026-09-30: 6787 of 7142 lines across 72 files of the application package. The pipeline floors the same figure at 90 percent, so the outside reading and the gate measure one report.

SonarCloud

The quality gate is OK on main, judged on code changed since 2026-09-23. The analyzer runs from the pipeline on the same commit the other gates judged, and it imports the same coverage report. Findings are triaged in the analyzer: a real one is fixed in the code, and a false positive is accepted there with its reason written, never silenced in the source.

Condition on new code Threshold Actual Status
reliability rating at most 1 1 OK
security rating at most 1 1 OK
maintainability rating at most 1 1 OK
coverage at least 80 95.0 OK
duplicated lines density at most 3 0.9 OK
security hotspots reviewed at least 100 100.0 OK
Measure, whole project Value
lines of code 15501
open reliability findings 0
open security findings 2
security hotspots to review 0
open maintainability findings 3
duplicated lines, percent 1.2
coverage as the analyzer measures it, percent 95.0

The analyzer's coverage figure counts the frontend, which has no coverage tool of its own and is tested through the application suite, so it reads below the Codecov figure for the same report.

Refreshing this page

python3 scripts/render_scoring.py --fetch   # re-read every rater, then render
python3 scripts/render_scoring.py --check   # what the gate runs

The fetch needs a checkout of build-doctrine beside this repository for the doctrine scorer; everything else is read from the raters' public interfaces. The rendered page and the snapshot commit together, and the gate refuses a page the snapshot does not produce.